logo

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

ID: abae2907-69cb-5f0e-8ef8-22ccf69ad756

STIX ID: report--abae2907-69cb-5f0e-8ef8-22ccf69ad756

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: [email protected] (The Hacker News)

...
...

A heap-based buffer overflow (CVE-2026-14266) in 7-Zip's XZ decoder can allow code execution if a victim opens a crafted XZ archive; the flaw stems from incorrect output-buffer length handling in MixCoder_Code and was fixed in 7-Zip 26.02. ZDI rates it 7.0 (High) but the attack vector is local (AV:L), has high complexity, requires user action, and as of July 20, 2026 there is no public proof-of-concept or reported exploitation in the wild — administrators should manually update any systems or vendors that bundle the vulnerable decoder.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.